View Single Post
Old 05-03-2004, 11:53 AM  
VideoJ
Confirmed User
 
Join Date: Aug 2002
Location: S. Florida
Posts: 750
Finally got rid of the little fucker.

Norton wouldn't get it, Mccaffe didn't find it, finally had to dig in a do it myself. I even tried the hand removal method and that didn't work, it kept coming back.

Simplest way to test wheather it's this virus, do a search on virus at google, if the win-dow closes right away you got it. Getting rid of the fucker is a two step process.

You want two pieces of software

KillProcess at http://home.swipnet.se/killprocess/
.hijack this (from download.com

First you have to kill the copy running. Use KillProcess for this as ctrl-alt-del doesn't work (the virus hides the process manager)

You look for wininit32.exe and kill it. might be called something else but that is what is what it was called in my machine. You can do the virus search test to see if that killed it.

Now run HijackThis. It will give you a list of possible problems in you computer. Look in the HKLM\..Run section, this is all stuff run when your computer starts up. Most are probalby ok, but look for the things that don't show a full directory path (c:\Program Files\...) The wininit32 ones and there is one that is named something weird (like [xlaq] fqe.exe). Click on those and click Fix checked.

Be careful here, if you're not very comfortable working on your computer, you may want to get a techie friend to do this.
VideoJ is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote